What we collect, why we collect it, and what you can ask us to do about it.
Selraiz is operated by [COMPANY NAME], registered at [REGISTERED ADDRESS], company number [COMPANY NO.], VAT number [VAT NO.].
For any question about this policy or about personal data, contact privacy@selraiz.com. Our data protection contact is [DPO CONTACT].
Selraiz plays two different roles, and which one applies changes your rights.
If you talked to a Selraiz agent on someone else's website and want your data deleted, the fastest route is to contact that website's operator. You can also contact us and we will pass the request to them and assist.
| What | Why |
|---|---|
| Name, email address, password hash | To create and secure your account |
| Workspace name and agent configuration | To run the service you configured |
| Content you upload for training - website URLs, documents, product data, text | To build the knowledge your agent answers from |
| Billing details and subscription status | To take payment and manage your plan. Card details are handled by Stripe and never reach our servers |
| Usage and diagnostic logs | To keep the service working, investigate faults and prevent abuse |
| Emails we send you - password resets, lead alerts, service notices | To operate your account |
When a visitor opens a Selraiz agent on one of our customers' websites, we process the following on that customer's behalf:
The agent identifies itself as an AI at the start of every conversation. Visitors are not required to provide contact details in order to get an answer.
Our customers configure what their agent asks for. We do not use visitor conversations to train models for other customers, and we do not sell any data.
Selraiz agents can speak and listen. Speech recognition and speech synthesis run in the visitor's own browser using the browser's built-in Web Speech capability. Audio is not uploaded to us and we do not store voice recordings. What reaches our servers is the resulting text, handled exactly like a typed message.
The browser vendor may process the audio to perform recognition. That processing is governed by the visitor's browser and operating system settings, not by Selraiz.
To generate a reply, the text of the conversation and the relevant extracts from the customer's training content are sent to a large language model provider. To find those extracts, text is converted into numeric embeddings by an embedding provider. Both are listed on our sub-processor page.
Model providers act on our instructions and are contractually prohibited from using this content to train their own models.
Agents answer from the customer's own trained content. They do not make automated decisions that produce legal effects or similarly significant effects on a visitor within the meaning of Article 22 GDPR.
We share personal data only with the sub-processors listed on our sub-processor page, each bound by a written contract, and with authorities where we are legally required to. We do not sell personal data or share it for advertising.
Your workspace, conversations, leads and training content are stored in AWS Frankfurt (eu-central-1) and remain there.
Some of our sub-processors - notably the model providers and our payment and email providers - are established outside the EEA. Where personal data reaches them, the transfer relies on an approved safeguard: the European Commission's Standard Contractual Clauses, an adequacy decision, or certification under the EU-US Data Privacy Framework. The specific safeguard for each provider is named on the sub-processor page. You can request a copy of the relevant safeguard from privacy@selraiz.com.
| Data | Retention |
|---|---|
| Account and workspace data | For as long as the account is open, then deleted within 30 days of closure |
| Conversations and captured leads | As configured by the customer; deleted within 30 days of account closure |
| Training content | Until the customer deletes the source, or the account closes |
| Billing and invoice records | Retained as required by tax law, typically [RETENTION PERIOD] years |
| Diagnostic logs | Up to 90 days |
Data is encrypted in transit (TLS) and at rest (AES-256). Access to production data is restricted to the personnel who need it. Passwords are stored only as salted hashes, never in a form we can read.
If a personal data breach occurs, we will notify the supervisory authority within 72 hours where required, and notify affected customers without undue delay.
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, port it elsewhere, or object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time without affecting what happened before.
Write to privacy@selraiz.com. We respond within one month. If you are unhappy with our response you may complain to your local data protection authority; ours is [SUPERVISORY AUTHORITY].
On selraiz.com we use only what the site needs to function - a session cookie once you sign in, and local storage to remember your preferences. We do not run advertising or cross-site tracking cookies.
The embedded agent uses browser storage on the customer's site to keep a conversation continuous across page loads. It can be configured in a cookie-free mode by the customer.
Selraiz is a business product and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, write to privacy@selraiz.com and we will delete it.
If we make a material change we will update the date at the top of this page and notify account holders by email at least 30 days before it takes effect.